One Federal Privacy Rule, Many State Laws
Coverage from PPC Land, Kronenberger Rosenfeld, and others

The SECURE Data Act, introduced in the U.
S. House in April 2026, would establish a federal framework for consumer personal-data privacy, including rights to access, correct, delete, and port data and opt out of certain data uses. It would also impose requirements such as consent for sensitive-data processing and create an FTC-administered data-broker registry. The proposal’s broad preemption of state privacy laws, combined with government-only enforcement and no private right of action, is a central point of debate over how a national standard would affect existing state protections.
The story has shifted from a general fight over federal preemption to a more specific debate over the SECURE Data Act’s enforcement mechanics and carveouts. The current version adds that the bill would rely on FTC/state AG enforcement, bar private lawsuits, and raise new concerns around data brokers, biometrics, and other sensitive-data rules.
The story is largely confirmed, but the current version adds clearer detail on the bill’s substantive limits and procedural exemptions, while identifying Hawaiʻi officials and the California Privacy Protection Agency as visible participants in the opposition landscape.
The story has become more concretely procedural: the SECURE Data Act is now described as moving through committee activity and hearings, with specific congressional proponents and opponents identified. Its substantive disputes and likely weaknesses remain largely unchanged.
The main update is a reframing of the SECURE Data Act from a bill that mainly preempts state privacy laws into one that more explicitly adds a national framework with expanded consumer rights and tighter federalized enforcement. The latest version also broadens the criticism to include biometric, AI, retention, and civil-rights concerns.
The story has sharpened from a general fight over federal privacy preemption into a more concrete legislative clash, with the current version adding specific enforcement details and clearer organized resistance from California officials and privacy groups. It now reads less like an abstract committee debate and more like an active push for a national standard facing coordinated state-level opposition.
The story has sharpened from a general federal privacy bill debate into a more specific legislative push, with new emphasis on a June 3 hearing and clearer details about the draft's enforcement and preemption contours. The main substantive change is the added prominence of data broker oversight and the framing of the bill as a single national standard that would override many state regimes.
The story is now framed less as a finished legislative push and more as an active, still-moving draft process, with hearings and revisions continuing. The new emphasis is on unresolved consumer remedies and safeguards, especially criticism that the bill lacks dark-pattern rules, opt-out signals, and stronger enforcement tools.
House Republicans have advanced the SECURE Data Act as a national privacy framework meant to replace a patchwork of state laws, but the bill is defined by disputes over preemption, enforcement, and how much protection it really adds. The clearest pattern is a push for federal uniformity through FTC and state attorney general enforcement, no private lawsuits, and new rules for opt-outs, sensitive data, and data brokers. Critics consistently argue the draft weakens stronger state protections, narrows remedies, and leaves major loopholes around consent, civil rights, and surveillance-prone data uses.
